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1.Which configuration file parameter can be used to modify line termination settings 
interactively, using the Set Source Type page in Splunk Web? 
A. LINE_BREAKER 

B. SHOULD_LINEMERGE 

C. BREAK_ONLY_BEFORE 

D. TRUNCATE 

Answer: A 


2.What is the name of the process that breaks the stream of raw data into individual 
lines called events? 

A. Line breaking 

B. Event annotation G 

C. Event transformation Ka 

D. Timestamp extraction Ka 

Answer: A s 


Ka 
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3.What is the name of the configuration file where yowan specify the source type for 
a data input? R 
A. limits.conf 
B. props.conf £ 
C. inputs.conf $ 
D. transforms.conf < 

Cà 
Answer: B «F 

N 
¥ 

4.What is the name of the Sptunk Cloud feature that allows you to get data from APIs 
and other remote data intéfiaces through scripted inputs? 
A. Splunk Cloud Data,@dnnectors 
B. Splunk Cloud Data Integrations 
C. Splunk Cloud, Jata Collectors 
D. Splunk Clout! Data Sources 
Answer: C 


5.Which configuration file needs to be edited to enable local indexing on the 
forwarder? 

A. outputs.conf 

B. inputs.conf 

C. props.conf 

D. transforms.conf 

Answer: B 


6.What is the name of the default field that stores the timestamps in UNIX time when 
data is indexed? 

A. _time 

B. timestamp 

C. date 

D. epoch 

Answer: A 


7.What is the name of the tab in Splunk Web where you can set the indexes that a 
role can access? 
A. Inheritance vw 
B. Capabilities Ka 

C. Indexes s 

D. Restrictions o 
Answer: C we 


9 
8.Which feature of forwarders can prevent datą jess in case of network failure or 
congestion? e 
A. Data compression $ 
B. SSL security $ 
C. Configurable buffering «F 
l H) 
D. Persistent queues K 
Answer: D Y 
ro 
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9.Which type of forwarder can act as an intermediate forwarder to receive data from 
other forwarders and’send it to the indexer? 
A. Universal forwétrder 
B. Heavy forwarder 
C. Light forwarder 
D. Any type of forwarder 
Answer: B 


10.Which type of forwarder can perform data parsing and enrichment before sending 
it to the indexer? 

A. Universal forwarder 

B. Heavy forwarder 

C. Deployment server 


D. Search head 
Answer: B 


11.Which setting in inputs.conf can be used to specify the SSL certificate for a TCP or 
UDP input? 

A. ssilCertPath 

B. ssIRootCAPath 

C. sslPassword 

D. All of the above 

Answer: D 


X 
12.What is the name of the component that acts as a data manage sends data 
to Splunk Cloud Platform indexers? ge? 
A. Heavy forwarder Ka 
B. Universal forwarder ¢ 
C. Deployment server © 
D. License master $ 
Answer: A o 
Z 
ev 
13.Which file processor can be used to ing files that are not actively written to or 
updated? <$ 


A. Monitor Ka 
B. MonitornoHandle K 
C. Upload Roa 
D. None of the above ie 
Answer: A RS 
x 
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14.Which type ofeforwarder is a full Splunk Enterprise instance that can run apps and 
add-ons? 

A. Universal forwarder 

B. Heavy forwarder 

C. Deployment server 

D. Search head 

Answer: B 


15.Which configuration file needs to be edited to configure the universal forwarder to 
act as a deployment client? 
A. deploymentclient.conf 


B. server.conf 
C. outputs.conf 
D. inputs.conf 
Answer: A 


16.Which command can be used to install a universal forwarder on a Linux system? 
A. splunk install forwarder 

B. splunk forwarder install 

C. splunk add forward-server 

D. splunk enable boot-start 

Answer: D 
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17.Which setting in inputs.conf can be used to specify the commafid to run the script 
for a scripted input? 


4 
A. script oY 
S 
B. command © 
C. exec $ 
D. run a 
Answer: A Ka 
N 
£ 
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18.What is the main advantage of self-service Splunk Cloud over managed Splunk 
Cloud in terms of cost and control? «f 

A. Self-service Splunk Cloud cosismore to get started and maintain but allows your 
organization total control in setup and security configurations. 

B. Self-service Splunk Clou@tosts less to get started and maintain and allows your 
organization total controlif setup and security configurations. 

C. Self-service Splunk oud costs more to get started and maintain and requires 
your organization tavely on Splunk for setup and security configurations. 

D. Self-service Sptunk Cloud costs less to get started and maintain but requires your 
organization tovely on Splunk for setup and security configurations. 

Answer: B 


19.Which option in Splunk web can be used to access the Guided Data On-boarding 
feature? 

A. Add data 

B. Data inputs 

C. Data summary 

D. Data models 

Answer: A 


20.Which Windows-specific input type allows Splunk software to read special 
Windows log files such as the DNS debug server log? 

A. MonitorNoHandle 

B. Windows Event Log 

C. Windows Registry 

D. Windows Management Instrumentation (WMI) 

Answer: D 


21.What is the name of the dashboard that provides information on incoming data 
consumption and indexing rate for your Splunk Cloud Platform deployment? 

A. Indexing Performance < 

B. Indexing Quality ge? 

C. Indexing Status s$ 

D. Indexing Overview o 
Answer: D oe 


9 
22.Which configuration file determines how a universal forwarder forwards data to the 
indexer? e 
A. inputs.conf g 
B. outputs.conf < 
Cà 
C. props.conf «F 
H) 
D. transforms.conf K 
Answer: B Y 
ro 

D 

~ 
23.What is the name ofthe attribute that specifies the sed script for data 
transformation in the props.conf file? 
A. SEDCMD oe 
B. FORMAT ® 
C. DEST_KEY 
D. TRANSFORMS 


Answer: A 


24.Which setting in inputs.conf can be used to specify the interval at which the script 
runs for a scripted input? 

A. interval 

B. frequency 

C. schedule 


D. cron 
Answer: A 


25.Which Splunk add-on simplifies the process of getting data into Splunk Cloud 
Platform from Windows Event Log channels? 

A. Splunk Add-on for Windows 

B. Splunk Add-on for Infrastructure 

C. Splunk Add-on for Active Directory 

D. Splunk Add-on for DNS 


Answer: A 
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